PT-2021-4099 · Unknown+1 · Cyrus Imap+1

Published

2021-05-05

·

Updated

2025-05-06

·

CVE-2021-32056

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Cyrus IMAP versions 3.2.7 and earlier, 3.3.x, and 3.4.x before 3.4.1
Description The issue allows remote authenticated users to bypass intended access restrictions on server annotations, which can cause replication to stall. This is related to incorrect permission assignment for a critical resource. Exploitation of the issue may allow a remote attacker to cause a denial of service.
Recommendations For Cyrus IMAP versions 3.2.7 and earlier, update to version 3.2.7 or later. For Cyrus IMAP version 3.3.x, update to version 3.4.1 or later. For Cyrus IMAP version 3.4.x before 3.4.1, update to version 3.4.1 or later.

Fix

Incorrect Permission

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1975
ALT-PU-2021-1979
ALT-PU-2025-6164
BDU:2021-04683
CVE-2021-32056

Affected Products

Alt Linux
Cyrus Imap